10-06-2020 03:47 PM
Hello, Here are 2 questions about the FMC and FTD relationship.
1. When accessing the Device > Certificate section I noticed a cert that has a status of "failed". I tried re-enrolling it but it failed. I tried uploading it again and it failed. When attempting to push a deployment to the device it fails and returns:
Lina messages
FMC >> clear configuration session OBJECT
yoknet _test >> info : Session OBJECT does not exist.
FMC >> clear configuration session FMC_SESSION_1
yoknet _test >> info : Session FMC_SESSION_1 does not exist.
FMC >> clear configuration session FMC_SESSION_2
yoknet _test >> info : Session FMC_SESSION_2 does not exist.
FMC >> no strong-encryption-disable
FMC >> ssl trust-point yoknet
yoknet _test >> error : ERROR: Trustpoint not enrolled. Please enroll trustpoint and try again.
ERROR: Trust-point is not enrolled.
Config Error -- ssl trust-point yoknet
Other logs
Lina configuration application failure log:
Platform settings were successful.
Lina Files Rollback successful
Rollback APP was successful.
A google search turned up someone with a similar issue and was told by Cisco TAC to run :
>expert
Password:
firepower:/home/root# pmtool restartbyid ngfwManager
This is supposed to fix the DB and is a way to recover from a "stuck" deployment.
###################################
2. I relocated and re-IP'd our FTD devices from the staging area to the server room. We got the IP's changed and the FMC sees these devices but they have disappeared from the the deployment choices. I can no longer deploy to the devices. This happened twice before and I was able to get them recognized by the FMC. In one case I simply restarted the FMC and in another I realized that the "platform assignment" didn't have those devices associated.
############################
Solved! Go to Solution.
10-06-2020 04:08 PM
Ha, fixed the one issue about the device not appearing in the deploy policy section. I just made a change to the interface section because of a miss-labeled port and it re-appeared like "maho". So that was easy.
ej
10-06-2020 04:08 PM
Ha, fixed the one issue about the device not appearing in the deploy policy section. I just made a change to the interface section because of a miss-labeled port and it re-appeared like "maho". So that was easy.
ej
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide